The last session I saw at HELish Summit 2026 was Sami Laiho, Chief Research Officer and Senior Technical Fellow at Adminize, Microsoft MVP for Windows OS since 2011 and for Security since 2024, at 16.00 in Runway 2 with “Cybersecurity – from Disabler to Enabler”. He said up front that this was a soft skills session combined with a technical one: less about the bits he normally teaches, more about the mindset that makes people understand, respect and even like the security department. This is my recap. The cases and the numbers are his, at the level of anonymity he used on stage.

Three phrases he wants gone
The first is “no as a service”, a Danish colleague’s term for what security departments usually are. Sami’s point was that the no is human: it is the only answer that guarantees the person saying it cannot be blamed later. He has met bank CISOs whose first rule was that nobody in security may use the word no.
The second is “we need to see what they do”: true, and never to be said aloud, because it turns every monitoring discussion into Big Brother.
The third is the one he said he hates to his guts: “the biggest security issue is people”. An uneducated user is a risk, he agreed, but the phrase lets security hide behind users who were never told how the system works. His example was a large Finnish healthcare provider, where an employee walked office to office every morning with a pile of doctors’ smart cards and their PINs, logging every doctor in because it took too long. Nobody had explained to her what the cards were for.
Support function, not the function
Security is a support function. The money is made on the factory floor, and a security team that can stop a refinery because a device is not updated has forgotten who pays its salary. That leads to the line he built the rest of the talk on:
Your job is not to stop the enemy, but to slow it down.
If you believe you can keep the attacker out, you skip monitoring and logging, the opposite of assume breach. So you stack seven controls of 95 percent instead of one of 100. The attacker has to move sideways, hack a bit, move sideways again, and in a SOC that watches a baseline, sideways movement is an anomaly a human can spot. Make your enemy an anomaly.
Communication is everything
His rule of thumb is that security is about 25 percent technology and 75 percent psychology, and most of the psychology is wording. Years ago he told 400 City of Helsinki nurses and library staff that passwords must be “difficult enough”. A colleague took him aside afterwards: you say strong, never difficult, because if you tell people something is difficult, it becomes difficult.
Removing developers’ admin rights lands badly if you open with “you are the biggest threat”; open with the fact that their SSDs will last longer. He admitted it can take him a day to find the positive angle for a control, and that the hardest is tiering: two accounts becoming six, all with MFA, has no nice wrapping. For that one he sometimes has to show what happens 30 milliseconds after a domain admin logs on to a compromised box.
BitLocker got the same treatment. People think it is about data and that they have none on the machine. He calls that a misunderstanding: its primary job is integrity, the epoxy that stops someone booting into recovery and lifting the AppLocker policy files out of System32. Your grandmother walks out of the electronics store with an encrypted laptop for her recipes, while enterprise architects tell him there is not enough data to warrant it. And the computer nobody uses for anything is the attacker’s favourite. If you had an empty rental flat, would you still lock it?
Rules people can accept
MFA makes the password a smaller worry, and NIST’s 2025 guidance forbids asking humans to rotate passwords at all, up from “not recommended” in 2017. Sami turns that into a deal: no more forced changes in exchange for strong ones, and if the company has a breach, everyone resets. Nobody wants to be the person in the coffee room whose click made that happen.
Least privilege is his favourite. “If I don’t have admin rights I can’t fix my computer” becomes “if you don’t have admin rights you can’t break your computer”. The fear is always more tickets. His counter-examples: a Danish customer around 2018 measured a 75 percent drop in tickets the year after removing admin rights, and a customer with about 10,000 computers emailed him that they could now buy a shorter service desk, because reinstallations fell 65 percent and the space went to a ping-pong table. And a warning to the room: last year ransomware groups targeted service desk staff for their admin rights; this year the target is developers, because the desk no longer has them.
Application control, and what surgeons need
Anti-malware tries to identify more than a million new bad things a day. Application control is the opposite: a list of what you trust. His most complex customer, with restaurants and manufacturing, runs on 280 lines. Microsoft’s vulnerability reports for last year, he said, contain not a single vulnerability that could have executed on a machine with application control in place; the year before it was around 99.8 percent. The technology is easy; the people part is not. He was once paid to stand in front of 400 employees and say the admin rights removal had been his idea, so that the internal IT team would not carry the anger.

The two cases on the slide were his examples of communication failing. At a university hospital in western Finland, IT and Sami decided Spotify would not be allowed; this is a hospital, not a playground. The next time he visited, a surgeon in scrubs came to him and said either you allow Spotify or people die. Surgeons concentrate with music on, and nobody had asked them. At a Finnish pharmaceutical company full of patents, a month of application inventory showed SAP first, the line-of-business system second, and 3D Pony Simulator third. His ten-year-old daughter knew what it was. Everyone’s kids needed it.
PAM and privileged access workstations

Privileged access management is, in his words, basically what NIS2 requires: sessions can be recorded and privileges granted only when needed. Admins hate the idea until it is deployed, then ask for more portals to be put behind it, because it becomes the one place where all their work lives. Privileged access workstations are not ruggedised laptops; they are separation of duties. You do not read Facebook on the machine that can wipe the tenant. His daughter needs an Intune-compliant device and MFA to scribble in OneNote, while the school’s outsourcing partner could delete the whole tenant from anywhere. Four of the five most expensive security incidents of the last five years were caused by a security product; after CrowdStrike, his PAW customers were glad they had them.
All of it, he said, is zero trust, which is a terrible name for a concept that should have been sold as working the same way wherever you are.
Tatu Seppälä’s 15.00 session on insider threat covered the same ground from the inside, and the two talks belong together. Sami is a friend and a fellow MVP, and this was the session of the day I would send to a security team that still says no.